EoRezo

Posted: November 7, 2011
Threat Metric
Threat Level: 2/10
Infected PCs 2,888,376

EoRezo Description

EoRezo Screenshot 1EoRezo, also known as eoRezo, is a browser add-on that's distributed with GrabIt, an Usenet news server search utility. As adware, EoRezo may not be as damaging to your PC as a keylogger or virus. Although EoRezo may offer a removal utility for itself, it's suggested that you avoid taking EoRezo at its word and, instead, delete EoRezo with a responsible anti-malware program.
 

EoRezo: New Adware with Outdated Tricks to Show Off

EoRezo was first noted in October of 2011 and is often distributed with French versions of GrabIt installation packages. Although EoRezo may promote itself as a search enhancer or other kind of beneficial tool, EoRezo's features are entirely negative for your PC and include unpleasantly-invasive tactics like:

  • Taking control of your web browser away from you to redirect you to other websites. This includes creating advertisement pop-ups and changing your homepage or search engine settings.
  • Sending information about your PC out to third parties (most likely to allow them to target their advertisements to your online habits).
  • Connecting to external servers for instructions without your permission. Two known affiliates of EoRezo include alpha00001.com and, naturally, eorezo.com. It goes without saying, of course, that you should avoid these websites whenever it's possible to do so.

You may also experience worse Windows or web browser performance, since many of EoRezo's actions will occur in the background and eat up memory without giving you an option to disable them.
 

The Antidote to EoRezo's Browser Additions

SpywareRemove.com malware analysts stress the necessity of keeping your anti-malware programs up-to-date if you want them to be able to identify and remove EoRezo. Although some of EoRezo's symptoms may manifest in a particular web browser, deleting your browser will not delete EoRezo, which will remain in the background and continue to suck up your system resources.
 
If you're dealing with an EoRezo infection, you should try to minimize any contact that you have with EoRezo affiliates, including advertisements and the sites that these advertisements offer links towards. These sites can include scamware-selling websites or sites that use phishing techniques to steal private information. However, if you immediately scan your PC with a suitable anti-malware program to find and get rid of EoRezo, all EoRezo-related symptoms, including the presence of advertisement-based pop-ups, should cease.

Aliases


Adware/BHO [Panda]Adware/EoRezo.A.72 [AntiVir]Application.Generic.384998 [BitDefender]Win32:Eorezo-B [PUP] [Avast]TROJ_SPNR.30DG12W32/Suspicious_Gen2.QREZPAdware.EoRezo!ggby8ZKOpU0Generic5.GFU [AVG]Win32.Malware [Ikarus]Win32/Adware.EoRezo.NAdware:Win32/EoRezo [Microsoft]Win32.Troj.Agent.jk.(kcloud)Adware.Win32.EoRezo.AMN (A)Adware/EoRezo.N.2 [AntiVir]Trojan.Win32.Generic!BT
More aliases (65)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to EoRezo may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

Download SpyHunter's Malware Scanner

Note: SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware tool to remove the malware threats. Learn more on SpyHunter. If you would like to uninstall SpyHunter for any reason, please follow these uninstall instructions. To learn more about our policies and practices, visit our EULA, Privacy Policy and Threat Assessment Criteria.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\microsoft office\9w7qhrk4npxmyhrw8c4lkl\da2-y93atm.exe\da2-y93atm.exe File name: da2-y93atm.exe
Size: 69.12 KB (69120 bytes)
MD5: 68518535700af96f78aab5ba356eb6be
Detection count: 2,155
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\microsoft office\9w7qhrk4npxmyhrw8c4lkl\da2-y93atm.exe\
Group: Malware file
Last Updated: September 1, 2020
%PROGRAMFILES%\Windows Photo Viewer\U13C4NSLJU420TD24Q9HM2PLL9D\c9-08bX_Uq.exe\c9-08bX_Uq.exe File name: c9-08bX_Uq.exe
Size: 1.57 MB (1578496 bytes)
MD5: acb795c9a587100bbe9daf9b3de86fbe
Detection count: 1,632
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Photo Viewer\U13C4NSLJU420TD24Q9HM2PLL9D\c9-08bX_Uq.exe\
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES%\internet explorer\4f53dg7pzh3\8ov_n0c&rn.exe File name: 8ov_n0c&rn.exe
Size: 111.61 KB (111616 bytes)
MD5: dd0d67502265c9b55183dd0257489b19
Detection count: 1,436
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\internet explorer\4f53dg7pzh3\
Group: Malware file
Last Updated: April 27, 2020
%COMMONPROGRAMFILES%\N5M7KN\Yq5gPZjCvX.exe\Yq5gPZjCvX.exe File name: Yq5gPZjCvX.exe
Size: 146.94 KB (146944 bytes)
MD5: 98b9644afd4de7674189556ca819b8e1
Detection count: 836
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\N5M7KN\Yq5gPZjCvX.exe\
Group: Malware file
Last Updated: August 31, 2020
%PROGRAMFILES(x86)%\formation\274031367.exe File name: 274031367.exe
Size: 5.39 MB (5392896 bytes)
MD5: 44032440596aa42cbb4bae2ff902b25b
Detection count: 796
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\formation\
Group: Malware file
Last Updated: April 26, 2020
%PROGRAMFILES%\windows photo viewer\o36sxetenz2agfm32nn3yo4aopltu0tvfi\nr-x#m8vsq.exe File name: nr-x#m8vsq.exe
Size: 238.59 KB (238592 bytes)
MD5: b88955cbf36ca817df7ab5d64415b056
Detection count: 792
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\windows photo viewer\o36sxetenz2agfm32nn3yo4aopltu0tvfi\
Group: Malware file
Last Updated: June 24, 2020
%PROGRAMFILES%\7-zip\38by5\+frxkz8#-m.exe File name: +frxkz8#-m.exe
Size: 604.16 KB (604160 bytes)
MD5: 6ced69cedb214f99015dc43a008e399f
Detection count: 618
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\7-zip\38by5\
Group: Malware file
Last Updated: July 9, 2020
%COMMONPROGRAMFILES%\md4gzv8zw\w9#vmmvçps.exe File name: w9#vmmvçps.exe
Size: 545.79 KB (545792 bytes)
MD5: c47c904c27b70bce5f4ca0a4d97ff659
Detection count: 607
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\md4gzv8zw\
Group: Malware file
Last Updated: June 30, 2020
%PROGRAMFILES%\k-lite codec pack x64\19xcr4a7jp7\&p#oqrzfgf.exe File name: &p#oqrzfgf.exe
Size: 216.06 KB (216064 bytes)
MD5: 205d9b12e59328c8e57ac92aa16ee3f8
Detection count: 438
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\k-lite codec pack x64\19xcr4a7jp7\
Group: Malware file
Last Updated: April 12, 2020
%SYSTEMDRIVE%\Users\USER\AppData\Local\Temp\LYFPI9RRVS\LYFP.exe\LYFP.exe File name: LYFP.exe
Size: 541.69 KB (541696 bytes)
MD5: b70ba5c079f815e03a95e004723404ad
Detection count: 398
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\USER\AppData\Local\Temp\LYFPI9RRVS\LYFP.exe\
Group: Malware file
Last Updated: August 31, 2020
%PROGRAMFILES%\poweriso\wd6zepwzeutrhojbipia9ej61x419a0zwk264a0j764bz\w0c_p5k1#a.exe File name: w0c_p5k1#a.exe
Size: 238.59 KB (238592 bytes)
MD5: ba4fc752a7d74b9a67b7f6a1a8075660
Detection count: 356
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\poweriso\wd6zepwzeutrhojbipia9ej61x419a0zwk264a0j764bz\
Group: Malware file
Last Updated: March 24, 2020
%PROGRAMFILES%\windowspowershell\d4pebmnuz6zfpmsn4a6gldtk52fw5xo0e\2brkriuga_.exe File name: 2brkriuga_.exe
Size: 206.33 KB (206336 bytes)
MD5: e280f49856c7cb7dd7de659742957ecd
Detection count: 323
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\windowspowershell\d4pebmnuz6zfpmsn4a6gldtk52fw5xo0e\
Group: Malware file
Last Updated: April 15, 2020
%PROGRAMFILES%\tap-windows\rs3tlurqbqf5rmztr2v\owajxdaa'o.exe File name: owajxdaa'o.exe
Size: 290.3 KB (290304 bytes)
MD5: 5003ed514dae595cf15c0b68af607b62
Detection count: 199
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\tap-windows\rs3tlurqbqf5rmztr2v\
Group: Malware file
Last Updated: July 8, 2019
%PROGRAMFILES%\Windows Mail\VPER3IM7BVRF13QK03TBX7A1PCUXT9VHIICMBZJ\z79hbçt-s#.exe \z79hbçt-s#.exe File name: z79hbçt-s#.exe
Size: 536.06 KB (536064 bytes)
MD5: 190f8a1dc601f30ad7e3768fbcf8ea6e
Detection count: 33
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Mail\VPER3IM7BVRF13QK03TBX7A1PCUXT9VHIICMBZJ\z79hbçt-s#.exe \
Group: Malware file
Last Updated: June 26, 2020
%PROGRAMFILES%\optic\714338509.exe\714338509.exe File name: 714338509.exe
Size: 486.4 KB (486400 bytes)
MD5: f56bcfa60e398b14e1b746e68b9329e6
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\optic\714338509.exe\
Group: Malware file
Last Updated: June 27, 2020
%PROGRAMFILES(x86)%\charkoucha\710282148.exe File name: 710282148.exe
Size: 571.39 KB (571392 bytes)
MD5: f47425b1b9b9e6b8da09110c404858ae
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\charkoucha\
Group: Malware file
Last Updated: August 23, 2019
%PROGRAMFILES(x86)%\zbidi\550802537.exe File name: 550802537.exe
Size: 515.07 KB (515072 bytes)
MD5: 5589be52bae041ddad72cc24e0845d08
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\zbidi\
Group: Malware file
Last Updated: October 9, 2019
%PROGRAMFILES%\omek\516459642.exe File name: 516459642.exe
Size: 703.48 KB (703488 bytes)
MD5: dd6c5e4a7cad80c8b4949f4d13952359
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\omek\
Group: Malware file
Last Updated: August 23, 2019
%PROGRAMFILES(x86)%\docroto\247435605.exe File name: 247435605.exe
Size: 799.23 KB (799232 bytes)
MD5: 1179589e86eb3a7e03b6c89e2586ebfb
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\docroto\
Group: Malware file
Last Updated: August 23, 2019
%PROGRAMFILES(x86)%\avkzd\582164585.exe File name: 582164585.exe
Size: 714.75 KB (714752 bytes)
MD5: b53bdabd915570eeb2f60a86761240f9
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\avkzd\
Group: Malware file
Last Updated: August 23, 2019

More files

Registry Modifications


The following newly produced Registry Values are:

Directory%ALLUSERSPROFILE%\AppApcVerifier%ALLUSERSPROFILE%\Application Data\AppApcVerifier%APPDATA%\EoRezo%APPDATA%\lighteningplayer%LOCALAPPDATA%\combroadcaster%PROGRAMFILES%\Ajc%PROGRAMFILES%\BeCleaner%PROGRAMFILES%\bestDownloader%PROGRAMFILES%\browseextension%PROGRAMFILES%\Caster%PROGRAMFILES%\ComoBo%PROGRAMFILES%\comoBoss%PROGRAMFILES%\documentss%PROGRAMFILES%\elansurfer%PROGRAMFILES%\EoRezo%PROGRAMFILES%\KokoMoss%PROGRAMFILES%\Koruko%PROGRAMFILES%\lightcleaner%PROGRAMFILES%\LighteningPlayer%PROGRAMFILES%\Speedycar%PROGRAMFILES%\texttotalk%PROGRAMFILES%\tuto100_ar_21%PROGRAMFILES%\WeatherInspect%PROGRAMFILES%\WinCaster%PROGRAMFILES%\YEha%PROGRAMFILES(x86)%\Ajc%PROGRAMFILES(x86)%\BeCleaner%PROGRAMFILES(x86)%\bestDownloader%PROGRAMFILES(x86)%\browseextension%PROGRAMFILES(X86)%\Caster%PROGRAMFILES(x86)%\ComoBo%PROGRAMFILES(x86)%\comoBoss%PROGRAMFILES(x86)%\documentss%PROGRAMFILES(x86)%\elansurfer%PROGRAMFILES(x86)%\EoRezo%PROGRAMFILES(x86)%\KokoMoss%PROGRAMFILES(x86)%\Koruko%PROGRAMFILES(x86)%\lightcleaner%PROGRAMFILES(x86)%\LighteningPlayer%PROGRAMFILES(x86)%\Parklands%PROGRAMFILES(x86)%\Speedycar%PROGRAMFILES(x86)%\texttotalk%PROGRAMFILES(x86)%\tuto100_ar_21%PROGRAMFILES(x86)%\WeatherInspect%PROGRAMFILES(x86)%\WinCaster%PROGRAMFILES(x86)%\YEha%TEMP%\bestDownloader%UserProfile%\Local Settings\Application Data\combroadcasterRegistry keySOFTWARE\Classes\cibleSOFTWARE\Classes\tsckmnaSoftware\EoRezoSoftware\LightcleanerSOFTWARE\LighteningPlayerSoftware\MAL\SpeedycarSOFTWARE\Microsoft\2upsSOFTWARE\Microsoft\APreSamSOFTWARE\Microsoft\avboostcampaign114SOFTWARE\Microsoft\bestavicampaign563Software\Microsoft\BigTimeSOFTWARE\MICROSOFT\campaign9961SOFTWARE\Microsoft\DMunversionSOFTWARE\Microsoft\DskFXSoftware\Microsoft\EtsySOFTWARE\Microsoft\FstCarSOFTWARE\Microsoft\MPrForShutTSoftware\Microsoft\MPrForWeathISoftware\Microsoft\MTPreC_BSoftware\Microsoft\MTPreC_QnSOFTWARE\MICROSOFT\multitimercampaign84170SOFTWARE\Microsoft\PrAmNPSOFTWARE\Microsoft\PShutdTimeSOFTWARE\Microsoft\shutdowntimecampaign5651Software\Microsoft\ShutTPreAmSoftware\Microsoft\ShutTPreIcSoftware\Microsoft\ShutTPreJSoftware\Microsoft\ShutTPreShMSOFTWARE\MICROSOFT\SpeedycarSoftware\MICROSOFT\TechnologyDesktopnewSOFTWARE\Microsoft\Tracing\AfficheOne_RASAPI32SOFTWARE\Microsoft\Tracing\AfficheOne_RASMANCSSOFTWARE\Microsoft\Tracing\i_network_RASAPI32SOFTWARE\Microsoft\Tracing\i_network_RASMANCSSOFTWARE\Microsoft\Tracing\LighteningMediaPlayerInstall_RASAPI32SOFTWARE\Microsoft\Tracing\LighteningMediaPlayerInstall_RASMANCSSOFTWARE\Microsoft\Tracing\o_network_RASAPI32SOFTWARE\Microsoft\Tracing\o_network_RASMANCSSOFTWARE\Microsoft\Tracing\wizzcaster_RASAPI32SOFTWARE\Microsoft\Tracing\wizzcaster_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpeedycarSOFTWARE\Microsoft\Windows\CurrentVersion\Run\WeatherInspectSOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}SOFTWARE\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}Software\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}}Software\Picture\PictureprocessingToolsV1.0Software\Picture\seescenicelfcSoftware\Picture\seescenicelfqSoftware\Picture\seescenicelfuSOFTWARE\T4pcSoftware\UniversalCadastSOFTWARE\Wow6432Node\EoRezoSOFTWARE\Wow6432Node\Microsoft\DMunversionSOFTWARE\Wow6432Node\Microsoft\PrAmNPSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\SpeedycarSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\WeatherInspectSOFTWARE\Wow6432Node\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}SOFTWARE\Wow6432Node\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}Software\Wow6432Node\Microsoft\{94ebd7b5-82ae-449t-b679-3d04078ed154}}SOFTWARE\Wow6432Node\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d}SYSTEM\ControlSet001\Services\AppApcVerifierSYSTEM\ControlSet002\Services\AppApcVerifierSYSTEM\CurrentControlSet\Services\AppApcVerifierFile name without pathlightcleaner.lnklightcleanerlightcleaner.exelightcleanerlightcleaner.tmpLightening Media Player.lnkLighteningMediaPlayerInstall.exeSpeedycar.lnkHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}bestDownloader_is1comoBoss_is1eoEngine_is1eoRezo_is1LighteningPlayermaintenance software_is1Speedycar_is1texttotalkWeatherInspect_is1Regexp file mask%PROGRAMFILES%\filters\xec.exe%PROGRAMFILES%\host\idscservice.exe%PROGRAMFILES%\host\w_network.exe%PROGRAMFILES%\host\wizzcaster.exe%PROGRAMFILES(x86)%\app\Wizard.exe%PROGRAMFILES(x86)%\filters\xec.exe%PROGRAMFILES(x86)%\host\idscservice.exe%PROGRAMFILES(x86)%\host\wizzcaster.exe%PROGRAMFILES(x86)%\pf\oo.exe%PROGRAMFILES(x86)%\Pipe\[NUMBERS].exe%TEMP%\avboost[RANDOM CHARACTERS].exe%TEMP%\speedycar[RANDOM CHARACTERS].exe%TEMP%\texttotalk.exe%USERPROFILE%\Desktop\texttotalk.lnk%WINDIR%\System32\Tasks\GoogleUpdateSecurityTaskMachine_[RANDOM CHARACTERS]CLSID{18AF7201-4F14-4BCF-93FE-45617CF259FF}{8FF10FED-2F0A-4F7F-BE87-B04F1DCD4319}{C10DC1F4-CCDF-4224-A24D-B23AFC3573C8}{DF76E9B7-35EC-46FC-AF56-5B79DED9D64F}

Leave a Reply

Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter. If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.